In performing scoping, what should the assessor ensure that the scope of the assessment covers?
A C3PAO has completed a Limited Practice Deficiency Correction Evaluation following an assessment of an OSC. The Lead Assessor has recommended moving deficiencies to a POA&M. but the OSC will remain on an Interim Certification. What is the MINIMUM number of practices that must be scored as MET to initiate this course of action?
During an assessment, which phase of the process identifies conflicts of interest?
Which organization is the governmental authority responsible for identifying and marking CUI?
During assessment planning, the OSC recommends a person to interview for a certain practice. The person being interviewed MUST be the person who:
In late September. CA.L2-3.12.1: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application is assessed. Procedure specifies that a security control assessment shall be conducted quarterly. The Lead Assessor is only provided the first quarter assessment report because the person conducting the second quarter's assessment is currently out of the office and will return to the office in two hours. Based on this information, the Lead Assessor should determine that the evidence is;
An OSC has submitted evidence for an upcoming assessment. The assessor reviews the evidence and determines it is not adequate or sufficient to meet the CMMC practice. What can the assessor do?
Prior to conducting a CMMC Assessment, the contractor must specify the CMMC Assessment scope by categorizing all assets. Which two asset categories are always assessed against CMMC practices?
Which phase of the CMMC Assessment Process includes the task to identify, obtain inventory, and verify evidence?
The Level 1 practice description in CMMC is Foundational. What is the Level 2 practice description?